Director, App Security
TKO · New York, NY · 1 mo ago
Information Technology$143k/yrFull-time
About the Role
We are looking for a hands-on Director, Application Security Engineering to strengthen our cybersecurity posture and partner directly with teams building software across web, mobile, data, and AI-enabled workflows. This role will embed security into delivery practices, improve how we prevent and remediate risk, and communicate clearly with both technical and non-technical stakeholders. This is a hybrid role (3 days/week in-office) with preference given to candidates near a TKO office, including NYC, Stamford, Orlando, Austin, or Las Vegas.
Responsibilities
- Own and evolve application security practices across the SSDLC, emphasizing scalable, developer-aligned, shift-left controls
- Operate and improve SAST, SCA, secret scanning, code scanning, repository protections, and related controls across repositories and CI/CD pipelines
- Develop secure development enablement for citizen developers, vibe coding, and AI-assisted development, including practical guidance for tooling, code assurance, identity, observability, and enterprise standards
- Review application and code-level vulnerabilities, validate findings, reduce noise, and drive risk-based remediation plans
- Conduct threat modeling and security design reviews for new systems, major changes, integrations, APIs, and high-risk workflows
- Advise teams on secure coding, authentication and authorization, session management, secrets handling, logging, encryption, dependency hygiene, and data protection
- Improve security guardrails for build pipelines, containers, APIs, third-party components, and deployment practices across modern and legacy environments
- Mature risk-based vulnerability management across intake, validation, prioritization, remediation guidance, exception handling, and reporting
- Support secure adoption of AI-assisted development and agentic systems by assessing trust boundaries, data exposure paths, prompt and tool-invocation risks, and misuse scenarios
- Develop pragmatic standards, playbooks, reference architectures, documentation, and office-hour support that improve consistency without slowing teams down unnecessarily
- Track recurring weaknesses, recommend structural fixes, and help leadership understand where engineering investment will reduce risk most effectively
- Use AI productively and responsibly to accelerate analysis, triage, documentation, coding support, and security review while maintaining strong human judgment
What Good Looks Like
- Engineering teams get faster, clearer, and more actionable security guidance as well as assistance with implementation and mechanics for a "teach a person to fish" approach
- Security tooling produces more trustworthy signals and leads to better adoption, not just more alerts
- Teams catch and remediate issues earlier in design and development rather than late in release cycles
- Application and agent-security risks are surfaced in practical terms with concrete mitigation paths
- Standards, playbooks, and tooling make secure delivery easier and more consistent
- Security becomes more embedded in day-to-day engineering execution and technical operations, and less dependent on last-minute security scrambles and efforts
Requirements
- 5+ years of hands-on experience in application security, product security, DevSecOps, and security engineering or a closely related software security role
- Proven experience working directly with engineering teams in fast-moving delivery environments
- Hands-on experience configuring, tuning, and operationalizing SAST, SCA, and related tooling such as SonarQube, Dependabot, GitHub, GitHub Advanced Security, or comparable platforms
- Ability to interpret and reason about code, identify meaningful risk, and provide specific, implementable remediation guidance to engineers
- Practical experience with SSDLC and shift-left practices, including automated code review support, threat modeling, security design review, and vulnerability management
- Strong understanding of application and API security, including common software weaknesses, authN/authZ, secrets handling, dependency risk, injection, deserialization, and data protection
- Experience integrating reliable, scalable, and minimally disruptive security controls into CI/CD pipelines and developer workflows
- Hands-on familiarity with cloud and modern software delivery patterns, including containers, IaC, and Git-based workflows
- Strong judgment in vulnerability triage, balancing severity, exploitability, business impact, and engineering realities
- Ability to write clear guidance, standards, and technical documentation for technical and non-technical audiences
- Bias toward automation, simplification, and scalable solutions over manual heroics
- Broad DevSecOps mindset across code, pipelines, dependencies, platforms, deployment, and operations
- Experience using AI tools responsibly to improve engineering and security outcomes
Preferred Qualifications
- Experience securing AI agents, LLM-enabled applications, copilots, or agentic workflows in production or near-production environments
- Experience with DAST, API security testing, penetration testing coordination, red-team support, or adversarial testing of application and AI systems
- Experience with policy-as-code, IaC scanning, container/image security, software supply-chain security, SBOMs, provenance, attestation, and secrets management
- Familiarity with cloud security across AWS and/or GCP and the application-layer implications of cloud-native architectures
- Experience in regulated, audit-sensitive, or event-critical environments where evidence, controls, and operational rigor matter
- Experience building metrics, dashboards, or reporting that show AppSec posture and remediation progress
- Experience mentoring engineers and influencing secure engineering culture without direct people management responsibility
Pay
Hiring rate range: $142,500 – $190,000 annually (minimum will not fall below the applicable State/local minimum salary thresholds).
Schedule
Hybrid role requiring 3 days per week in-office.